New Windows Error Reporting Vulnerability Lets Attackers Escalate to Gain SYSTEM Access
ID: c486222a-03f8-58db-b094-46f2b8add47d
STIX ID: report--c486222a-03f8-58db-b094-46f2b8add47d
Feed Name: cybersecurityNews.com
This report analyzes CVE-2026-20817, a local privilege escalation in WerSvc.dll that lets a low-privileged user abuse ALPC messages to cause Windows Error Reporting to start WerFault.exe with SYSTEM privileges; Microsoft mitigated the risk by disabling the vulnerable elevated-launch feature rather than patching it. The write-up includes exploitation details (ALPC APIs, message flags, file-mapping handle duplication), detection notes (process parent spoofing alerts, Defender signatures), and warnings about malicious proof-of-concept repositories.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
